Incorrect Regular Expression in Symfony - CVE-2026-45065
Published: May 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to incorrect regular expression handling in UrlGenerator when validating route parameter values against regex alternation requirements during URL generation. A remote attacker can supply a crafted parameter value that passes validation and produces a protocol-relative URL to redirect users to an untrusted site.
The issue occurs because anchoring applies only to the first and last alternatives in an ungrouped alternation pattern.
Affected software
Debian Linux
symfony (Debian package)
How to mitigate CVE-2026-45065
symfony (Debian package) - addressed in versions 5.4.53+dfsg-0+deb12u1, 6.4.41+dfsg-0+deb13u1